Create Hosted API

Beta

Create a hosted API. The slug is a DNS label, globally unique on the shared domain (409 hosted_api_slug_taken) and immutable afterwards. Dark launch: requires the hosted_apis_access entitlement (402 hosted_apis_not_in_plan otherwise).

Authentication

AuthorizationBearer

Enter your API key with the Bearer prefix, e.g. ‘Bearer sk_…’.

Headers

Speechify-VersionstringOptional
Idempotency-KeystringOptional<=255 characters
A client-generated key (an opaque string, max 255 chars) that makes a side-effect POST safe to retry: the server runs the operation exactly once and replays the first response (its status and body) for 24 hours. Reusing a key with a different request body, or while the first request is still in flight, returns `409 idempotency_conflict`. A replayed response carries the `Idempotent-Replayed: true` header.

Request

This endpoint expects an object.
slugstringRequiredformat: "^[a-z0-9](?:[a-z0-9-]{1,38}[a-z0-9])?$"

3-40 lowercase letters, digits or hyphens; a DNS label, unique on the shared domain; immutable.

namestringRequired
descriptionstringOptional<=1000 characters
auth_modeenumOptional

consumer_key when omitted.

cors_originslist of stringsOptional
daily_run_capintegerOptional1-100000

Runs the API may start per UTC day through its run routes; 1000 when omitted.

project_idstringOptionalformat: "^proj_[0-9a-hjkmnp-tv-z]{26}$"

Response headers

Speechify-Request-IdstringOptional
Unique identifier for this request, present on every response (2xx and non-2xx alike). If the caller sends a `Speechify-Request-Id` request header the server echoes it back (sanitized and length-capped) so one logical request can be traced end-to-end; otherwise the server generates a fresh value. Log it on every response and quote it in support requests - it is the stable handle that ties your observation to Speechify's server-side logs, and it matches the `request_id` field in the error envelope. The legacy alias `X-Request-ID` carries the same value and is still accepted on requests, until 2027-07-24. Prefer the un-prefixed name (RFC 6648).

Response

The created API.
idstringformat: "^api_[0-9a-hjkmnp-tv-z]{26}$"
slugstring
hostnamestring

The public host, <slug>.<hosted-api domain>; empty where no domain is configured.

base_urlstring
namestring
descriptionstring
auth_modeenum

consumer_key: every request presents a ck_ bearer minted for this API. public: no credential; only read resolvers may be served, and the per-IP limiter is the only bound.

cors_originslist of strings

Browser origins allowed to call the API (* for any). Empty for server-to-server only.

enabledboolean
daily_run_capinteger1-100000

Runs the API’s run routes may start per UTC day; the spend ceiling behind a leaked consumer key.

project_idstring or nullformat: "^proj_[0-9a-hjkmnp-tv-z]{26}$"
created_atdatetime
updated_atdatetime

Errors

400
Bad Request Error
401
Unauthorized Error
402
Payment Required Error
404
Not Found Error
409
Conflict Error